BeaconSpec

← All articles

Agentic commerce • Field briefing

117 companies said they were agent-ready. None of them were.

Researchers asked 405 senior leaders in manufacturing and distribution whether they were prepared for AI agents. A hundred and seventeen said fully prepared. When the claim was held against an operational bar, the number that cleared it was zero.

David Soden  •  Agentic commerce  •  7 min read
An electronic scoreboard on a stand in an empty hall, both sides lit up showing a score of zero.
Everyone in the room was sure of the score. Nobody had checked it.

A benchmark published this month put the question to 405 senior marketing, technology and data leaders across industrial manufacturing and wholesale distribution in the US and Europe. Among them, 117 said their organization was fully prepared for agentic commerce. The researchers then held that claim against what the operation could actually do: whether product data stays current, whether it moves end to end without a person patching it by hand, whether the catalog is continuously publishable. Not one of the 117 cleared the bar.

The supporting numbers show how a gap that size happens quietly. About half of the group hit product-data integration failures at least monthly. Only 13.6% run end-to-end automation with an audit trail. Fewer than one in three keep more than 85% of their active SKUs continuously publishable. The study comes from inriver, which sells product information management software and therefore has an interest in the answer, but the sample and the method are stated, and the direction matches everything else measured this year.

Every one of those 117 companies was certain. Every one of them was wrong.

What's happening

Self-assessment just stopped being the only measure available.

On August 23 Vercel and an agent-research firm called Ora put a scorecard on the open web. You type a domain into is-agentic.com and it grades that site on whether an AI agent can find it, get into it, understand it and pay it. The checks adapt to what the site turns out to have: an API, an OAuth flow, a GraphQL endpoint, an MCP server, a developer portal, a commerce surface. The ranker behind it has already scanned more than 16,000 domains. No login, no API key, no bill.

Two things separate that from the readiness rankings that came before it. It works on any domain rather than a fixed list of large retailers, so a mid-size distributor is now as scoreable as Target. And it comes from Vercel, the platform a large share of the world's front-end engineers already deploy on, which makes it much harder for anyone inside a company to dismiss as a vendor selling the fix.

The same week, Microsoft Advertising published a 90-day agentic commerce playbook. First 45 days on foundations, meaning product feeds and a checkout that actually completes. Second 45 on tuning. Three things it tells a business to work on, in order: get discovered by the agent, make the purchase go through, measure it. Microsoft anchored the whole document on Bain's forecast that 15% to 25% of US ecommerce runs through AI agents by 2030.

What's changed since our last briefing

Last time you couldn't get in. This time you can't keep it quiet.

Our last briefing covered Google wiring thirteen outside apps into Gemini with no application process for anybody else. The only lever a business had was what it publishes, because nobody was taking applications. Since then that lever got a public gauge bolted onto it. Your board can pull your number. So can an analyst, a partner deciding who to integrate with next, and the competitor building their next deck.

The reading also refuses to stay still. ReFiBuy published its second-quarter retailer readiness rankings on August 18 and led with how much they had reshuffled in three months. The standards underneath are still moving, so a score is a reading rather than a certificate, which is the part most people get wrong when they file this as a project with an end date.

A hand holding a magnifying glass over printed account statements spread across a wooden desk, reading the detail line by line.
The number was always there. Until this month, getting at it took a consultant and a few weeks.

The confidence gap, measured

Organizations that described themselves as fully prepared for agentic commerce, against the number that met the operational benchmark.

117 0 Said they were fully prepared for AI agents Actually met the operational benchmark

Source: inriver Product Data Maturity Benchmark, 405 senior marketing, technology and data leaders in industrial manufacturing and wholesale distribution across the US and Europe, published August 5, 2026. The same study found only 13.6% run end-to-end automation with audit trails and fewer than one in three keep more than 85% of active SKUs continuously publishable. inriver sells product information management software, so treat its conclusions as vendor research; the sample and method are stated, and the 0-of-117 finding is the one worth carrying.

Why this matters to you

The traffic is already arriving, and it never files a complaint.

Target told its August 19 earnings call that digital traffic arriving from outside AI platforms grew more than three and a half times faster than the industry rate year over year, which it credited to early work with OpenAI, Google Gemini and others. Guest traffic up 3.6%, comparable sales up 3.8%, digital comparable sales up 8.7%. The company named its first chief AI officer in the same week. Walmart made similar noises. When a public retailer starts quantifying this on a call, budgets follow within a quarter or two.

Now the other half of the picture, because your own engineers will raise it and they should. Forrester's mid-2026 read is that most so-called agentic experiences are still conversational, and that very few consumers currently let an agent finish a purchase unsupervised. A merchant survey in June put AI-involved transactions at roughly 3% of UK and US volume, and that figure came from a vendor blog, so hold it loosely. The volume is not here yet. What is here is the measurement, the standards and the partner choices, and all three get settled before the volume shows up. Being late to this costs considerably more than being early does.

What an agent-readiness score actually checks

Four questions, asked of your site by a machine, in about ten seconds.

DISCOVERY Can an agent find you at all, and what you sell? ACCESS Is there a way in that isn't a login form built for a human? USABILITY Can it read your catalog and your terms without guessing? PAYMENTS Can the order actually go through, inside a real account? All four are settled by what you publish. None of them are settled by the agent, and none of them are settled by a marketing page.

Pillars as described by Vercel and Ora for the is-agentic checker, launched August 23, 2026. The checks run conditionally against whatever the site turns out to expose, including an API, an OAuth flow, a GraphQL endpoint, an MCP server or a commerce surface.

The question worth asking before any of this

Watching the conversation is not the same as controlling the actions.

One more thing happened this month, and it changes how a careful business should frame the whole subject. At Black Hat, researchers demonstrated taking over the AI shopping assistant of a top-three US retailer. The retailer was not careless about it. There was a gateway in front of the model, classifying intent, reading every prompt and every response. The researchers skipped the conversation entirely and went at the execution layer, meaning the set of operations the assistant was permitted to call. The gateway never fired, because nothing suspicious was ever said out loud.

So before you let an agent act for your customers, the question to answer is not what it can say. It is what it can call, and who wrote that list. Most businesses have never been asked it and cannot answer on the spot, which is a fine place to be in August 2026 and a bad place to still be in a year.

A close-up of a grey industrial control panel with labelled dials, toggles and switches, each one a deliberate, separate control.
Curation is a short, deliberate list of things an agent may do, written by you and nobody else.

Why we're built for this

A published interface is the part of the score you control.

BeaconSpec is the discovery layer for agentic commerce. Point us at the REST, OpenAPI or GraphQL APIs your business already runs. We turn them into one curated server an agent can call and publish it as a UCP server card at your own /.well-known, so ChatGPT, Gemini or Perplexity can discover it without anybody at those companies picking you first. UCP is the open standard Google, Shopify, Walmart and Target are building on.

Two parts of that matter more than the plumbing, and Black Hat sharpened both. The first is curation: you decide exactly which operations an agent can ever see, and nothing outside that list exists as far as the agent is concerned. An open endpoint over your whole API is exposure, not a strategy. The second is the sign-in, because real commerce needs the shopper actually logged in before "where is my order" or "place my order" means anything. We handle the standard login handshake so the agent acts inside your customer's own account, with no shared passwords and no separate build for each AI vendor.

Run it hosted by us, or take a sealed container and run it inside your own walls if the data cannot leave. And since the specs keep moving quarter to quarter, keeping the surface current is our job rather than a standing ticket for your engineers. That is the difference between a score you passed once and a surface that stays passing.

A smaller, separate thing worth doing

One pillar of any readiness score is whether an agent is permitted to reach you at all, and that one is set by a text file most people have never opened. On September 15 Cloudflare's default flips for sites that never wrote their own rules. Answer three plain questions and our AI Visibility Checker writes a correct robots.txt for you.

Check your AI visibility →

No sign-up. Copy the result and paste it into your site.

The one thing to remember

117 companies were certain they were ready. Zero of them were.

Self-assessment was the only measure anybody had, and it was wrong a hundred and seventeen times out of a hundred and seventeen. As of this month the check is free, instant, and available to your competitors and your board without anyone asking you first.

The part of the score you actually control is what you publish: a curated, standards-compliant interface any agent can discover, use and buy through, with you deciding exactly what it can see and do.

The thing worth watching now is whether that free score becomes the number everyone quotes. If it does, "we think we're fine" stops being an answer anybody accepts, and the businesses already publishing a real interface will be the ones with nothing to explain. If it does not, the number is still sitting there for anyone curious enough to pull it, which in a competitive market is the same outcome arriving more slowly.

BeaconSpec exists for exactly this shift: making your business discoverable and transactable by AI agents over UCP, on an interface you publish and control, instead of hoping the self-assessment holds.

See what we do  •  Try the free AI Visibility Checker  •  Read more articles


David Soden writes about automation, web strategy, and building durable technical systems for businesses. Photography via Pexels (Tima Miroshnichenko, RDNE Stock project, Sean P. Twomey). Figures cited are drawn from inriver's Product Data Maturity Benchmark (August 5, 2026), Vercel and Ora's is-agentic launch (August 23, 2026), Microsoft Advertising's agentic commerce playbook citing Bain (August 21, 2026), Target's Q2 2026 earnings call (August 19, 2026), ReFiBuy's second-quarter AI1000 rankings (August 18, 2026), Forrester's "The State Of Agentic Commerce In Mid-2026", and security press reporting of the Black Hat 2026 AI agent findings.